Law / United States /
New York
DFS Guidance: How to Conduct and Use Risk Assessments Required by the DFS Cybersecurity Regulation
DFS Industry Letter of on Risk Assessments
Guidance, not a law: the New York Department of Financial Services's reading of New York Department of Financial Services Cybersecurity Regulation, Cybersecurity Program and Cybersecurity Policy. It binds nobody by itself; the law it reads does.
Guidance on a sector security regimes rule, addressed to private bodies.
- Instrument type
- guidance published by a regulator
- Obligation class
- Security, Governance, DPIA
As of .
What the regulator expects
- The letter is addressed to all entities the Department regulates, and it reads 23 NYCRR Part 500, which reaches you if you operate as a Covered Entity under 23 NYCRR 500.1(e): any person operating under, or required to operate under, a license, registration, charter, certificate, permit, accreditation or similar authorization under the Banking Law, the Insurance Law or the Financial Services Law, regardless of whether you are also regulated by other government agencies (reached by declaring that you provide financial services). The Department states that the letter does not create new obligations.
- The Department says you must maintain a cybersecurity program based on your risk assessment and designed to protect the confidentiality, integrity and availability of your information systems and the nonpublic information stored on them, and that performing risk assessments is an integral, mandatory element of that program (23 NYCRR 500.2 and 500.9).
- The Department says you must review and update your risk assessment as reasonably necessary, at least annually, and at a minimum whenever a change in your business or technology causes a material change to your cyber risk; it gives major system migrations, mergers or acquisitions, significant outsourcing arrangements, significant developments in cybersecurity technologies such as frontier AI models, changes in threat actor capabilities and the adoption of emerging technologies as examples of material changes.
- The Department says you must carry out the risk assessment under written policies and procedures that include criteria for evaluating and categorizing identified cybersecurity risks or threats, criteria for assessing the confidentiality, integrity, security and availability of your information systems and nonpublic information, including the adequacy of existing controls, and requirements describing how identified risks are addressed by your cybersecurity program (23 NYCRR 500.9(b)).
- The Department says you must use the results of the risk assessment to inform the design and implementation of, and updates to, your cybersecurity policies, procedures, controls and testing plans, and the assessment must inform and support your decisions on control selection, compensating controls and risk acceptance; it expects you to be able to demonstrate how it did.
- The Department says you must maintain documentation sufficient to demonstrate how cybersecurity risks were identified, assessed and addressed through the risk assessment process, including records that link each identified risk to the controls or compensating measures implemented; it says the documentation should also capture any risk you accept, with the justification and any residual risk considerations.
- The Department says you are required to maintain an accurate and current asset inventory, and that the inventory should serve as the foundational input to the risk assessment, with consideration of where nonpublic information resides, how it flows through your information systems, who has access to assets and how assets are protected.
- The Department says your risk assessment should cover all assets, emerging risks, third-party risk and concentration risk, and be tailored to your size, complexity, unique risks, operations and assets.
- The Department says your risk assessment should evaluate risks associated with third-party service providers by the criticality of the services provided, the sensitivity of the information accessed or maintained, the level of connectivity to your information systems and the potential operational impact if the provider experiences an incident or disruption, and should identify single points of failure and assess concentration risk.
- The Department says you should adopt a clear and repeatable methodology, although it does not require a specific one, that defines at a minimum reasonable estimates of the likelihood and impact of risks and applies consistent rating criteria; and it says you should evaluate both external and internal threats.
- The Department says your written policies and procedures must be approved at least annually by a senior officer or your senior governing body, that, where applicable, you must designate a chief information security officer or a senior officer to oversee the risk assessment process, and that the chief information security officer must report material cybersecurity risks to the senior governing body (23 NYCRR 500.4(b)(3)); it adds that Part 500 does not require formal approval of risk assessments from a board of directors or senior management.
Who enforces it
Enforcement body
The Superintendent of Financial Services, who enforces 23 NYCRR Part 500, the regulation the letter reads.
What this law does
The Department's industry letter of is addressed to all entities the Department regulates and gives guidance on how to conduct and use the risk assessments its cybersecurity regulation requires. The Department says it issued the guidance to clarify regulatory requirements and highlight best practices when designing, conducting and updating risk assessments. The letter states that it does not create new obligations.
It says Part 500 requires a cybersecurity program designed to protect the confidentiality, integrity and availability of a covered entity's information systems and the nonpublic information stored on them, as section 500.2(a) provides. It calls the performance of risk assessments an integral, mandatory element of that process. For its description of the risk assessment duties the letter cites section 500.9(a) and (b) of Part 500.
It says risk assessments must be sufficient to inform the design of the covered entity's cybersecurity program. It says risk assessments must be carried out in accordance with written policies and procedures that include criteria for evaluating and categorizing risks, criteria for assessing the confidentiality, integrity, security and availability of information systems and nonpublic information, and requirements describing how identified risks are addressed by the cybersecurity program.
It says the risk assessment must inform and support the covered entity's decisions regarding control selection, compensating controls and risk acceptance. The Department says it expects each covered entity to be able to demonstrate how its risk assessment informed cybersecurity controls, compensating controls and risk acceptance decisions. It says risk assessments should be tailored to an organization's size, complexity, unique risks, operations, assets and other circumstances.
It says the Department reviews covered entities' risk assessments and information security policies and procedures during examinations and investigations. It says the Department has identified common gaps in risk assessments that have contributed to deficient cybersecurity programs. The gaps include incomplete asset scope and visibility, including outdated or incomplete asset inventories and failing to identify where nonpublic information resides or flows.
The gaps include weak or inconsistent methodologies, including failing to consistently identify, analyze, prioritize and document cybersecurity risks. The gaps include a failure to account for evolving and interconnected risks, including emerging technologies, changes in the threat landscape, interdependencies, concentration risk and single points of failure.
The gaps include insufficient governance and risk treatment, including failing to assign ownership, document risk response decisions and integrate risk assessment results into enterprise governance. The gaps include a failure to account for or inform the cybersecurity program, resulting in policies, controls and resource decisions that are not demonstrably based on the covered entity's identified cyber risks.
It says Part 500 requires covered entities to implement and maintain written policies and procedures that are approved at least annually by a senior officer or the covered entity's senior governing body. It says that, where applicable, covered entities must designate a chief information security officer or a senior officer to oversee the risk assessment process.
It says section 500.4(b)(3) requires the chief information security officer to report material cybersecurity risks to the senior governing body. It says Part 500 does not require formal approval of risk assessments from a board of directors or senior management. It says covered entities should adopt a clear and repeatable methodology for identifying, analyzing and prioritizing actions to address cybersecurity-related risks.
It says the methodology should define, at a minimum, reasonable estimates of the likelihood and impact of risks and apply consistent rating criteria so that results are measurable and comparable over time. It says the Department does not require covered entities to use a specific methodology in risk assessments. It says covered entities should evaluate both external and internal threats.
It says effective risk assessments should cover all assets, emerging risks, third-party risk and concentration risk. It says covered entities are required to maintain an accurate and current asset inventory, which should serve as the foundational input to the risk assessment. It says covered entities should also consider, as appropriate, where nonpublic information resides, how it flows through information systems, who has access to assets and how assets are protected.
It gives the adoption or use of artificial intelligence, advances in quantum computing that may affect future cryptographic protections, increasing software supply chain attacks, evolving ransomware techniques and significant geopolitical tensions as examples of emerging risks.
It says risk assessments should evaluate cybersecurity risks associated with third-party service providers based on the criticality of the services provided, the sensitivity of the information accessed or maintained, the level of connectivity to the covered entity's information systems and the potential operational impact should the provider experience an incident or other disruption.
It says covered entities should identify potential single points of failure, assess concentration risk and evaluate how a cybersecurity event affecting one dependency could impact other information systems or critical business functions. It says covered entities must maintain documentation sufficient to demonstrate how cybersecurity risks were identified, assessed and addressed through the risk assessment process.
It says that documentation includes records that link each identified cybersecurity risk to the specific controls or compensating measures implemented to mitigate it. It says the documentation should also capture instances where management elects to accept a risk, including the justification for risk acceptance and any residual risk considerations.
It says covered entities should maintain a mechanism, such as a risk register or comparable tracking process, to record assessment results, monitor remediation activities and document changes to residual risk over time. It says section 500.2 requires a covered entity's cybersecurity program to be based on its risk assessment so that the program may be designed to perform core cybersecurity functions.
It says covered entities must use the results of the risk assessment to inform the design and implementation of, as well as updates to, cybersecurity policies, procedures, controls and testing plans. It says covered entities must review and update risk assessments as reasonably necessary, but at least annually, and at a minimum whenever a change in their business or technology causes a material change to their cyber risk.
It gives major system migrations, mergers or acquisitions, significant outsourcing arrangements, significant developments in cybersecurity technologies such as frontier AI models, changes in threat actor capabilities and the adoption of emerging technologies as examples of material changes to cyber risk. It says the Department encourages covered entities to review their risk assessments and risk assessment procedures in light of the guidance.